Description
A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-06-29
Score: 5.3 Medium
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the /cgi-bin/wireless.cgi script of the Wavlink WL-NU516U1-A router. The subroutine sub_401D68 processes POST parameters SSID2G2, SSID5G2, AuthMethod2, and WPAPSK12, and an attacker can embed arbitrary shell commands into these parameters. The flaw allows the execution of those commands on the router’s firmware and therefore remote code execution. The vulnerability is described by CWE‑74 (Command Injection) and CWE‑77 (Improper Restriction of Operations within the Command Shell).

Affected Systems

The affected product is the Wavlink WL‑NU516U1‑A router running firmware version M16U1_V240425. The issue resides in the HTTP interface that processes POST requests to /cgi-bin/wireless.cgi. Only this model and firmware version are listed as vulnerable.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate baseline risk. The EPSS score of 1% indicates a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The official alert notes that the flaw has been publicly disclosed and that a fixed firmware revision has been released. The likely attack vector is remote HTTP POST traffic directed at the device’s web management interface, which is reachable from network or management plane connections.

Generated by OpenCVE AI on June 29, 2026 at 14:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the vendor‑supplied firmware update that fixes the wireless.cgi command injection flaw
  • If a firmware upgrade cannot be performed immediately, block or disable external access to the router’s web administration interface via a firewall or router configuration
  • Monitor system logs for unexpected POST requests or signs of anomalous command execution

Generated by OpenCVE AI on June 29, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-nu516u1
Vendors & Products Wavlink wl-nu516u1

Mon, 29 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 05:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection
First Time appeared Wavlink
Wavlink wl-nu516u1-a
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:wavlink:wl-nu516u1-a:*:*:*:*:*:*:*:*
Vendors & Products Wavlink
Wavlink wl-nu516u1-a
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wavlink Wl-nu516u1 Wl-nu516u1-a
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-29T13:48:00.057Z

Reserved: 2026-06-28T10:01:35.649Z

Link: CVE-2026-13538

cve-icon Vulnrichment

Updated: 2026-06-29T13:47:55.999Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T19:30:02Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')